CVE Database
/

CVE-2020-7656

Back to search

CVE-2020-7656

Published: May 19, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.

VendorProductVersions

n/a

jquery

affected
All versions prior to version 1.9.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now